Microsoft Certified:Azure Network Engineer Associate
Domain 5Objective 1
Implement and Manage Network Security Groups AZ-700 Practice Questions (Page 3)
Part of the Design and implement Azure network security services domain, which accounts for 15–20% of the AZ-700 exam. Microsoft does not publish an official question count, but from its 100-minute exam (~40–65 total, ~6–13 in this domain), expect 2–4 from this objective — we provide 28 practice questions to prepare you well beyond it. (estimate)
28questions here
6free pages
10concepts
15–20%of the exam
Questions 11–15
- 11
You need to allow remote administration of a Windows VM using RDP (port 3389) from the internet. What is the most secure way to configure this?
Select an answer first - 12
What is the primary purpose of Azure Virtual Network Manager (AVNM) security admin rules?
Select an answer first - 13
What is the default action for NSG security rules if no rule matches?
Select an answer first - 14
You need to configure an NSG to allow SSH (port 22) to a Linux VM from a specific IP address. What should you specify as the source in the inbound rule?
Select an answer first - 15
Your company runs a three-tier web application in Azure. The web tier VMs are in subnet A, the application tier VMs are in subnet B, and the database tier VMs are in subnet C. You need to ensure that the application tier VMs can only be reached from the web tier VMs, and that the database tier VMs can only be reached from the application tier VMs. You want to minimize the number of NSG rules and avoid hard-coding IP addresses. What should you do?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Microsoft. “AZ-700” is a trademark of its owner, used for identification only.